Identification-Driven External Attack Surface Discovery for Unknown Assets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity measures struggle to detect and protect against unknown and forgotten assets, entry points, and vulnerabilities in computing networks, which are often exploited by hackers.
Innovation Solution
A system and method that utilizes computational tools to discover and manage an organization's external attack surface by linking data from asset databases, domain name servers, and other sources, using AI and machine learning to autonomously assess and present the attack surface through a unified display.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional cybersecurity measures are used to detect network assets and vulnerabilities, then known assets can be identified, but unknown and forgotten assets remain undetected
Solution Approach 1:
The system performs preliminary actions by proactively querying multiple databases (WHOIS, Shodan, DNS services) and executing DNS searches before hackers can exploit unknown assets. This advance detection through automated reconnaissance identifies forgotten assets and vulnerabilities before they can be compromised, resolving the contradiction between detecting known assets and finding unknown assets.
Solution Approach 2:
The patent introduces intermediary computational tools and databases as mediators between the cybersecurity system and the target network assets. These intermediaries (asset databases, domain name servers, open-source tools) enable the system to indirectly discover unknown assets through multiple data sources, thereby improving detection accuracy without directly accessing the target network.
2Reliability
If multiple databases and tools are queried to discover all assets, then comprehensive coverage is achieved, but system complexity increases
Solution Approach 1:
The patent merges multiple databases (WHOIS, Shodan), DNS services, and open-source tools into a unified automated discovery system. By combining these disparate resources into a single coordinated workflow that executes DNS searches and queries multiple sources simultaneously, the system achieves comprehensive asset detection while managing complexity through integration rather than separate manual operations.
Solution Approach 2:
The system implements self-service through automated workflows that independently query multiple databases, execute DNS searches, and process results without requiring manual intervention. The automated nature of the system allows it to self-manage the complexity of coordinating multiple data sources, achieving reliable comprehensive detection while reducing operational burden.
3Productivity
If automated tools are used to scan IP addresses and domains, then vulnerability detection improves, but false positives may increase
Solution Approach 1:
The system incorporates feedback mechanisms by cross-referencing results from multiple databases and tools, and by using open-source tools to verify findings. This feedback loop allows the system to validate detected vulnerabilities against multiple data sources, reducing false positives while maintaining high detection efficiency through automated processing of the feedback information.
Data Source
AI summary
Disclosed are systems and methods for discovering one or more computing assets associated with primary identification data. The systems and methods comprise a series of processes and steps to discover an organization's external attack surface. The processes and steps include building a unique external attack surface management catalog to be used as a configuration value as a first step of discovering unknown internet-facing assets of an organization. Then the processes and steps include using the unique external attack surface management catalog in combination with open-source reconnaissance and proprietary scanners to determine the external attack surface of the organization. The disclosed systems and methods then uniquely present the acquired relevant data to users using a single display screen. The disclosed systems and methods not only discover the external attack surface and internet-facing assets of an organization and its aliases, but also internet-facing assets of related subsidiary, affiliate, and partner entities.


